
ShellUpload
PHP-based web shell uploader for penetration testing, enabling file upload and remote command execution on vulnerable web servers.

PHP-based web shell uploader for penetration testing, enabling file upload and remote command execution on vulnerable web servers.

PHP Webshell with handy features

Yet Another PHP Shell - The most complete PHP reverse shell

CVE-2025-3969: Exploit PoC (OS CMD injection, Web Shell, Interactive Shell)

CVE-2026-56290 - Mass Exploit for Joomla Com_pagebuilderck component (Unrestricted File Upload → RCE). Multi-threaded, automatic CSRF bypass, PHP…

Small PHP shell, Controlled by Python Client , connecting over protocol method

This is a powerful and stealthy PHP reverse shell designed for ethical hacking and penetration testing. It establishes a reliable and quiet…

Simple PHP reverse shell script for establishing remote command execution on target systems. Ideal for penetration testing and security assessments.

React2Shell - CVE-2025-66478 RCE Exploit

Exploit to trigger RCE for CVE-2018-16763 on FuelCMS <= 1.4.1 and interactive shell.

Proof-of-concept exploit for CVE-2025-57819 in FreePBX: SQL injection in the AJAX API to execute arbitrary PHP, create a persistent webshell, and…

Multi-threaded time-based blind SQL injection exploit for CVE-2026-14762 targeting Hotel & Tourism Reservation 1.0. Enumerates databases, tables,…

CVE-2026-48909 - Unauthenticated PHP Object Injection to RCE exploit for Joomla SP LMS extension versions <= 4.1.3. Exploits lmsOrders cookie…

Proof-of-concept exploit for CVE-2023-3824 (PHP phar deserialization) enabling remote code execution via crafted phar archive and reverse shell…